PT-2020-3585 · Canonical+2 · Apport+3

Ga_Ryo

+1

·

Published

2020-08-04

·

Updated

2025-01-31

·

CVE-2020-11936

CVSS v3.1

3.1

Low

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions gdbus versions (affected versions not specified) apport versions (affected versions not specified)
Description The issue is related to a privilege escalation in gdbus and an information disclosure vulnerability in the apport error reporting service. The apport vulnerability is caused by errors in the code and can be exploited through specially crafted D-Bus calls, allowing an attacker to read arbitrary files.
Recommendations For gdbus, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For apport, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

BDU:2020-03919
CVE-2020-11936
USN-4449-1
USN-4449-2
ZDI-20-978

Affected Products

Linuxmint
Ubuntu
Apport
Gdbus